aboutcode-org / aboutcode-org/scancode-toolkit

Support npm dependencies with "weird" versions

未关闭
#2,509 0 条评论 0 个 reaction 已指派 0 人 在 GitHub 查看
bug dependencies package scan package-formats
主要语言
Python
星标
2.6k
派生
791
平均合并
1 天 12 小时
30 天内合并 PR
5

描述

Per https://docs.npmjs.com/cli/v7/configuring-npm/package-json#dependencies the version of a dependency can be various things:

- URLs as Dependencies: "http://asdf.com/asdf.tar.gz",
- Git URLs as Dependencies: See https://docs.npmjs.com/cli/v7/configuring-npm/package-json#git-urls-as-dependencies ... this is using a VCS_URL-os-SPDX and pip-like syntax
- GitHub URLs: user/repo#feature\/branch
- Local Paths: "bar": "file:../foo/bar" ....

These versions end up in the package-lock.json too and they are not really versions.
We should instead treat them as requirements and not as concrete versions.

This is also impacting ScanCode.io BTW

贡献指南

打开贡献指南

评估

这个 Issue 还没有评估数据。

把新 issue 发到你的邮箱

精选适合新手参与的 GitHub issue 摘要。